Types & Classification Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Types & Classification flashcards as text
Which ACL type filters traffic based solely on source IP address?
Answer: Standard ACL
Standard ACLs filter traffic using only the source IP address as the matching criterion.
What is the number range for Cisco extended IP ACLs?
Answer: 100–199
Cisco extended IP ACLs use numbers in the range 100–199 (and 2000–2699 for expanded range).
A reflexive ACL is best described as which type?
Answer: A stateful ACL that automatically permits return traffic for established sessions
Reflexive ACLs create temporary dynamic entries that allow return traffic matching an established outbound session.
Which classification describes an ACL that uses a name string instead of a number?
Answer: Named ACL
Named ACLs allow administrators to assign a descriptive string identifier rather than a numeric ID.
Dynamic ACLs (lock-and-key) differ from standard ACLs because they:
Answer: Require user authentication before opening a temporary access hole
Dynamic (lock-and-key) ACLs open a temporary permit entry only after a user authenticates, typically via Telnet.
Which ACL type is most appropriate for filtering traffic close to the destination host?
Answer: Extended ACL
Extended ACLs should be placed close to the source, but their granular matching (source, destination, port) makes them ideal for precise destination-side filtering when needed.
Time-based ACLs add which dimension to standard ACL filtering?
Answer: Active hours or day-of-week schedules
Time-based ACLs use time-range objects to activate or deactivate permit/deny rules during specified hours or days.